< Back to all clusters
[TECHNOLOGY] · Uganda · 3 sources

Critical Flaws Found in BlackBerry UEM, WordPress Plugin, and ManageEngine

A cross‑site scripting (XSS) vulnerability (CVE‑2026‑18084) was disclosed in BlackBerry UEM Management Console versions prior to QF9. An unauthenticated attacker can inject malicious JavaScript that, when viewed by an administrator, steals session tokens and can take over the console. The Uganda National CERT urges immediate deployment of the QF9 patch, IP‑based access restrictions and multi‑factor authentication.

A supply‑chain backdoor (CVE‑2026‑18072) was found in the Advanced Responsive Video Embedder WordPress plugin version 10.8.7. The malicious code allows any remote attacker to bypass authentication, impersonate an administrator and relay the compromised site URL and admin username to a fonts.wp.com command‑and‑control server. Wordfence reported the issue within two hours of detection and the plugin was removed from the WordPress.org repository.

ManageEngine ADAudit Plus (CVE‑2026‑6516) contains an authentication‑bypass and path‑traversal flaw that enables remote code execution on builds earlier than 8606. The vulnerability scores a CVSS v3.1 of 10.0. ManageEngine advises upgrading to build 8606 and updating associated Windows and macOS agents.

Entities: Advanced Responsive Video Embedder · Advanced Responsive Video Embedder WordPress plugin · BlackBerry Ltd · BlackBerry UEM Management Console · Fontswp.com · ManageEngine (Zoho Corporation) · ManageEngine ADAudit Plus · Uganda National Computer Emergency Response Team · WordPress.org · Wordfence

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

  • [○ 1 SOURCE] CVE‑2026‑18084 is a cross‑site scripting vulnerability in BlackBerry UEM Management Console versions prior to QF9. (BlackBerry UEM vulnerability article)
  • [○ 1 SOURCE] CVE‑2026‑6516 is a pre‑authentication remote‑code‑execution vulnerability in ManageEngine ADAudit Plus builds prior to 8606, with CVSS 10.0. (CVE‑2026‑6516 | ManageEngine ADAudit Plus)
  • [○ 1 SOURCE] CVE‑2026‑18072 is a supply‑chain backdoor in the Advanced Responsive Video Embedder WordPress plugin version 10.8.7, rated CVSS 9.8. (WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2)
  • [○ 1 SOURCE] Exploitation of CVE‑2026‑6516 may allow an unauthenticated attacker to write files outside intended directories and execute code; no confirmed active exploitation has been reported. (CVE‑2026‑6516 | ManageEngine ADAudit Plus)
  • [○ 1 SOURCE] The backdoor allows an unauthenticated attacker to impersonate a WordPress administrator and send site URL and admin username to an attacker‑controlled server. (WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2)
  • [○ 1 SOURCE] Exploitation of CVE‑2026‑18084 can allow an unauthenticated attacker to execute JavaScript in an admin’s browser and potentially steal session tokens and take over the console. (BlackBerry UEM Management Console – Cross‑Site Scripting (CVE‑2026‑18084) | Uganda National Computer Emergency Response)
  • [○ 1 SOURCE] CVE-2026-18084 is a cross‑site scripting vulnerability in BlackBerry UEM Management Console before version QF9 that allows unauthenticated remote attackers to inject malicious JavaScript and take over (BlackBerry UEM vulnerability)
  • [○ 1 SOURCE] The Uganda National CERT recommends applying the QF9 patch, enabling MFA, restricting console IP access, and monitoring logs to mitigate CVE-2026-18084 (Uganda CERT advisory)
  • [○ 1 SOURCE] CVE-2026-6516 is a pre‑authentication remote‑code‑execution vulnerability in ManageEngine ADAudit Plus Agent APIs affecting builds before 8606 with CVSS 10.0 (ManageEngine vulnerability)
  • [○ 1 SOURCE] The backdoor sends the compromised site’s URL and selected administrator username to the C2 server fontswp.com (WordPress plugin backdoor)
  • [○ 1 SOURCE] CVE-2026-18072 is a supply‑chain backdoor in the Advanced Responsive Video Embedder WordPress plugin version 10.8.7 that gives unauthenticated attackers full administrator access (WordPress plugin backdoor)
  • [○ 1 SOURCE] ManageEngine released patch build 8606 to fix CVE-2026-6516 and advises users to upgrade (ManageEngine remediation)